CVE-2025-5734: TOTOLINK X15 HTTP POST Request formWlanRedirect buffer overflow
Published Jun 6, 2025
·Updated
A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
TOTOLINK X15
All of the following
TOTOLINK X15 Firmware=1.0.0-b20230714.1105
TOTOLINK X15
Event History
Jun 6, 2025
CVE Published
via MITRE·07:31 AM
Data Sourced
via MITRE·07:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Feb 20, 57488
Event
via FIRST·09:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5734?
CVE-2025-5734 is classified as a critical vulnerability.
2
How does CVE-2025-5734 affect TOTOLINK X15 devices?
CVE-2025-5734 affects the HTTP POST Request Handler in TOTOLINK X15 devices.
3
What is the impact of exploiting CVE-2025-5734?
Exploitation of CVE-2025-5734 can lead to a buffer overflow vulnerability.
4
How do I fix CVE-2025-5734?
Fixing CVE-2025-5734 involves applying the latest firmware update provided by TOTOLINK.
5
Which version of TOTOLINK X15 is affected by CVE-2025-5734?
CVE-2025-5734 affects TOTOLINK X15 version 1.0.0-B20230714.1105.